ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

AI summary · glm-5.3-flash

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

  • CVE-2026-20030 (CVSS 10.0) is SQL injection in Crosswork platforms
  • CVE-2026-20357 and CVE-2026-20358 also rated CVSS 10.0 in Crosswork
  • Secure Workload fixes include CVE-2026-20315 and CVE-2026-20317 (CVSS 10.0)
  • Fixed in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16
  • No active exploitation reported; flaws found in internal testing

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20357
+3 in the same advisory: …20030 …20358 …20359
Missing Authentication for Critical Functions in Cisco Crosswork

CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

Do: Review Cisco's August 19, 2026 Crosswork advisory for the affected version list and upgrade to the software hardening release it specifies, since version details are not included in this data. Until patched, restrict network access to Crosswork management interfaces and monitor Cisco PSIRT for updates. No workarounds or in-the-wild exploitation are documented at this time.

10.0
group max
<1%
  • Cisco Crosswork
nichelikely hundreds to low thousands of enterprise/service-provider deployments (specialized platform; exact install base unknown)
CVE-2026-20317
+4 in the same advisory: …20315 …20231 …20318 …20319
Improper Authentication Flaws in Cisco Secure Workload Score CVSS 10.0

CVE-2026-20317 covers multiple improper authentication issues (CWE-287) in Cisco Secure Workload, discovered internally by Cisco's engineering team during a comprehensive security review and addressed in a software hardening release. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H) indicates the flaws are exploitable over the network by an unauthenticated attacker with no user interaction, and the changed scope means successful exploitation can affect components beyond the vulnerable one. An attacker could gain high-impact modification of system state and denial of service across the deployment, though the vector indicates no direct confidentiality (data disclosure) impact. Users of Cisco Secure Workload are affected; the fix was published as part of Cisco's August 19, 2026 advisory batch, which reportedly patched nine Crosswork and Secure Workload flaws, five of which scored CVSS 10.0. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days (37th percentile).

Do: Review the Cisco Secure Workload security advisory (published August 19, 2026) for the exact affected and fixed release list, and upgrade to the corresponding software hardening release. Until patched, restrict network access to Secure Workload management and authentication interfaces to trusted administrative networks, since the flaw requires no authentication or user interaction. Given the CVSS 10.0 rating despite low current exploitation likelihood (EPSS 0.4%, no known PoC), prioritize patching within normal critical-vulnerability maintenance cycles.

10.0
group max
<1%
  • Cisco Secure Workload
nichelow thousands of enterprise deployments, with management/auth interfaces typically not internet-exposed
CVE-2026-20349
Unauthenticated Remote DoS in Cisco ASA/FTD SSL VPN Service

CVE-2026-20349 is a vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, caused by insufficient error checking when processing HTTP requests. An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the SSL VPN service on an affected device. A successful exploit causes the device to reload unexpectedly, resulting in a denial-of-service condition; no credentials or user interaction are required, and confidentiality and integrity are not affected. Any organization running ASA or FTD software with the Remote Access SSL VPN service enabled is affected, especially devices whose VPN interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11 and is reported as exploited in the wild, though no public proof-of-concept is known.

Do: Upgrade ASA and FTD devices to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-20349. Until patching is complete, verify whether the Remote Access SSL VPN service is enabled and internet-exposed, restrict access to trusted sources where possible, and check logs for unexpected device reloads. Federal agencies must apply mitigations per CISA BOD 26-04 timelines.

8.62% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
masson the order of 100,000s of internet-exposed ASA/FTD devices (only those with the Remote Access SSL VPN service enabled)
Full article443 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -

  • CVE-2026-20030 (CVSS score: 10.0) - An SQL injection vulnerability
  • CVE-2026-20357 (CVSS score: 10.0) - A missing authentication for critical function vulnerability
  • CVE-2026-20358 (CVSS score: 10.0) - An external control of file system vulnerability
  • CVE-2026-20359 (CVSS score: 9.9) - An insufficiently protected credentials vulnerability

The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.

Cisco has also released fixes to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments -

  • CVE-2026-20231 (CVSS score: 9.9) - A set of improper neutralization of special elements vulnerabilities spanning command, operating system, and argument injection
  • CVE-2026-20315 (CVSS score: 10.0) - A set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses
  • CVE-2026-20317 (CVSS score: 10.0) - A set of improper authentication vulnerabilities spanning missing authentication, authentication bypass, and reliance on untrusted inputs
  • CVE-2026-20318 (CVSS score: 9.6) - A set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control
  • CVE-2026-20319 (CVSS score: 7.5) - A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes

The five vulnerabilities have been patched in the versions below -

  • Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
  • Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16

"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.

The development comes about two weeks after Cisco resolved 12 bugs impacting Catalyst SD-WAN and IOS XE Software following the internal security review. The review, the networking equipment major added, has "resulted in software hardening releases that address multiple internally discovered vulnerabilities."

The prevalence of Cisco gear within enterprise networks makes it an attractive target for bad actors, who have repeatedly exploited dozens of flaws impacting its products to gain unauthorized access and deploy malware.

Earlier this month, Cisco warned that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html